CVE-2026-2734
published 2026-05-21CVE-2026-2734: In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model…
PriorityP341medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.44%
37.8th percentile
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and its omission from `GraphQLAuthorizationMiddleware.PROTECTED_FIELDS` for GraphQL. This vulnerability can expose sensitive information such as model names, version descriptions, source URIs, tags, and other metadata, potentially revealing proprietary or confidential details in multi-tenant environments. The issue is resolved in version 3.10.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | < 3.10.0 | 3.10.0 |
| lfprojects | mlflow | >= 0 < 3.10.0 | 3.10.0 |
| mlflow | mlflow_mlflow | >= unspecified < 3.10.0 | 3.10.0 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MLflow up to 3.9.x REST API BEFORE_REQUEST_VALIDATORS/AFTER_REQUEST_HANDLERS access control
vuldb·2026-05-21·CVSS 6.5
CVE-2026-2734 [MEDIUM] MLflow up to 3.9.x REST API BEFORE_REQUEST_VALIDATORS/AFTER_REQUEST_HANDLERS access control
A vulnerability has been found in MLflow up to 3.9.x and classified as critical. This vulnerability affects unknown code of the component REST API. Performing a manipulation of the argument BEFORE_REQUEST_VALIDATORS/AFTER_REQUEST_HANDLERS results in improper access controls.
This vulnerability was named CVE-2026-2734. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-w5xq-c4pf-ghq7: In mlflow/mlflow versions up to 3
ghsa_unreviewed·2026-05-21
CVE-2026-2734 [MEDIUM] CWE-284 GHSA-w5xq-c4pf-ghq7: In mlflow/mlflow versions up to 3
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and its omission from `GraphQLAuthorizationMiddleware.PROTECTED_FIELDS` for GraphQL. This vulnerability can expose sensitive information such as model names, version descriptions, source URIs, tags, and other metadata, potentially revealing proprietary or confidential details in multi-tenant environments. T
GHSA
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
ghsa·2026-05-21
CVE-2026-2734 [MEDIUM] CWE-284 MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and its omission from `GraphQLAuthorizationMiddleware.PROTECTED_FIELDS` for GraphQL. This vulnerability can expose sensitive information such as model names, version descriptions, source URIs,
Red Hat
mlflow: mlflow: Information Disclosure via improper authorization checks
vendor_redhat·2026-05-21·CVSS 6.5
CVE-2026-2734 [MEDIUM] CWE-639 mlflow: mlflow: Information Disclosure via improper authorization checks
mlflow: mlflow: Information Disclosure via improper authorization checks
A flaw was found in mlflow. An authenticated user could exploit a lack of proper authorization checks in the SearchModelVersions REST API and mlflowSearchModelVersions GraphQL query. This flaw allows them to enumerate all model versions across all registered models, potentially exposing sensitive information such as model names, descriptions, and other metadata. This could lead to the disclosure of proprietary or confidential details in multi-tenant environments.
Package: rhoai/odh-mlflow-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9 (Red H
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-45844 kernel: netfilter: arp_tables: fix IEEE1394 ARP payload parsing
bugzilla·2026-05-27
CVE-2026-45844 [MEDIUM] CVE-2026-45844 kernel: netfilter: arp_tables: fix IEEE1394 ARP payload parsing
CVE-2026-45844 kernel: netfilter: arp_tables: fix IEEE1394 ARP payload parsing
In the Linux kernel, the following vulnerability has been resolved:
netfilter: arp_tables: fix IEEE1394 ARP payload parsing
Weiming Shi says:
"arp_packet_match() unconditionally parses the ARP payload assuming two
hardware addresses are present (source and target). However,
IPv4-over-IEEE1394 ARP (RFC 2734) omits the target hardware address
field, and arp_hdr_len() already accounts for this by returning a
shorter length for ARPHRD_IEEE1394 devices.
As a result, on IEEE1394 interfaces arp_packet_match() advances past a
nonexistent target hardware address and reads the wrong bytes for both
the target device address comparison and the target IP address. This
causes arptables rules to match against garbage data
Bugzilla
CVE-2026-2734 mlflow: mlflow: Information Disclosure via improper authorization checks
bugzilla·2026-05-21·CVSS 6.5
CVE-2026-2734 [MEDIUM] CVE-2026-2734 mlflow: mlflow: Information Disclosure via improper authorization checks
CVE-2026-2734 mlflow: mlflow: Information Disclosure via improper authorization checks
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and its omission from `GraphQLAuthorizationMiddleware.PROTECTED_FIELDS` for GraphQL. This vulnerability can expose sensitive information such as model names, version descriptions, source URIs, tags, and other metadata, p
2026-05-21
Published